Pump.fun pauses trading after apparent flash loan attack

Pump.fun is “aware” that bonding curve contracts on Pump.fun were exploited, and has since paused trading

article-image

Dall-e modified by Blockworks

share

Pump.fun was attacked Thursday by an exploiter who seemingly used flash loans to buy out the bonding curve. 

In a post on X, Pump.fun said that it was “aware” that the contracts were compromised and were investigating. 

“We have upgraded the contracts so the attacker cannot siphon any more funds. The TVL in the protocol right now is safe,” the team said. “We’ve paused trading — you cannot buy and sell any coins at the moment. Any coins that are currently in the process of migrating to Raydium cannot be traded and will not be migrating for an indefinite period of time.”

Igor Igamberdiev, head of research at Wintermute, analyzed the situation in a series of posts on X, saying that the key was compromised, “though the possibility of an inside job remains.”

Loading Tweet..

Igamberdiev said that the amount lost by Pump.fun is “at least” 12,000 SOL, or roughly $2 million.

An account on X going by Stacc seemed to take credit for the attack, writing “I’m about to change the course of history” in a post

Stacc seemed to imply in his posts that he didn’t intend to keep the stolen funds, but rather planned to transfer the “remaining balances of bonding curves” to some token users. 

Loading Tweet..

It’s not clear as of publication how Stacc was able to execute the attack, or if they’re distributing the balances to random people. 

As Blockworks previously reported, Pump.fun lets developers launch tokens without seed liquidity for a couple of dollars. Its revenue comes from users buying and selling tokens. 

Tokens that exceed market caps of $69,000 can then be listed on the Raydium DEX. 

This is a developing story.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (1).png

Research

Aave’s revenues have doubled from April lows and are fast approaching all-time highs. With 35% of borrow interest coming from ETH and 55% from stablecoins, Aave is emerging as a powerful proxy as an ETH and stablecoin beta. As looping strategies accelerate growth and Horizon positions the protocol to ride the RWA wave, Aave is shaping up as one of DeFi’s most compelling multi-narrative plays.

article-image

Bitwise investment strategist expects end to “the wild-west phase of public companies …turning into crypto vehicles”

article-image

The first Solana treasury company is set to make its US debut

article-image

The Solana DAT reportedly plans to raise $1 billion

article-image

YO’s new yoEUR vault lands as incentives try to pull EURC onchain, but fragmented bridges and caps keep markets segmented

article-image

Astana regulator begins trial accepting USD-backed stablecoins for payments through Bybit integration

by Blockworks /
article-image

The Trump-backed DeFi project is believed to have blacklisted Sun’s wallet, triggering market pressure

by Blockworks /